ANSI/ASIS PAP.1-2012 Physical Asset Protection
Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection

ANSI/ASIS PAP.1-2012 Physical Asset Protection A.4.2: A.4.2 A formal, documented risk assessment process kept up to date

The organization should run and update a formal documented process for identifying, analysing and evaluating risk that: identifies risks from deliberate and accidental threats that could affect, directly or indirectly, its assets, operations, activities, functions and stakeholders (through threat, vulnerability and criticality analysis); analyses which risks significantly affect its activities and functions, its products and services, the supply chain, the environment and relationships with stakeholders; evaluates and ranks risks into four bands, namely intolerable (treated whatever the cost if the activity is to continue), as low as reasonably practicable (further reduction would cost out of proportion to benefit), tolerable (negligible or handled by routine procedures) and acceptable (taken on or kept by informed decision); and selects, evaluates and monitors controls and treatments against their costs and benefits. To keep the information documented, current and confidential, the organization should: keep checking whether scope, policy and risk assessment still fit the context; re-evaluate risks when things change inside the organization or around it, including its procedures, functions and services, its partnerships and supply chains, and its mutual aid arrangements; re-evaluate controls after risk events through investigation, treatment and management acceptance; weigh the direct and indirect costs and benefits of options that cut risk and raise reliability and resilience; make sure prioritised risks drive how the PAPMS is set up and run; and evaluate how well controls and treatments work.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 28000:2022 · 2 controls

  • 6.1.2 Determining security-related risks and identifying opportunities
  • 8.3 Risk assessment and treatment
  • 4.3.1 4.3.1 A formal, documented risk assessment and impact analysis with recovery time objectives

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.